security

kinshuksunil's picture

How Secure is Wordpress ?

A friend of mine is a web development service provider and a competitor of his, raised a question mark on Wordpress, which was being deployed for a specific project. The question raised was "Wordpress is not secure enough for commercial needs!". I am attaching my friends short reply to that question below:

---

Hi <customer>
I respect the expertise and experience of <my competitor>, however I cannot ignore the expertise, time and experience that IT teams working for big brands like CNN, The New York Times, Ford, NASA, Sony Playstation, Harvard and many more put in to choose the right platform for their content. For a complete list please, check the following links:

Almost 75% of blogs on the internet use Wordpress as a publishing platform. You can see more data on the following link

And when we say blogs, we just dont mean a horde of personal blogs - but immense blogs handling millions of users per day like - Tech Crunch, MakeUseOf.com, Giga OM Networks, amongst many others.

Other than that, if you wanna see how many Wordpress has been downloaded click on following link 

No software is perfect. Vulnerabilities and security loophole exist everywhere. Even companies like Google have been hacked, for more details click on the following link 
But, Wordpress is being developed by an active community consisting of thousands of developers. What this means is that the turnaround time for new features and vulnerability fixes is very short compared to any other commercial cms, usually averaging around a day only.

<customer>, At the end of the day the final call is yours. I still stand with my support for Wordpress. 

---

What do you guys think - How Secure is Wordpress? Leave a comment!

zubin71's picture

Security Exercises

Security exercises which happen around the globe at almost all times of the year come mainly in two forms :-

1. Web-Application based hacking

2. Capture the flag style hacking

 

Capture the flag(CTF) :- Two of the CTF exercises i have taken part in are :-

1. CIPHER5

2. HAR CTF

- What is a CTF?

zubin71's picture

Buffer Overflows - The way to go about it

Towards the beginning of this month, i was part of a team that had taken part in the CIPHER 5 capture the flag competition; due to lack of experience and preparation we had failed to fare well in it; we came out 22nd out of 32 worldwide.

zubin71's picture

netcat - an intro on the Swiss knife

Yup, so here i am again, this time with a tutorial on the tool which is named the "Swiss Army Knife" - netcat. I realize that there are many tutorials on this tool on the internet already, but i`ll try to present it from a security perspective. So, i`ll keep this nice and short; lets start.

rohit11's picture

Introduction to BackTrack

Introduction to the best compilation of best open source tools for hacking, investigation and forensic.

As ClubHack calls it "from local boot to remote root in one CD" :)

Note: If required this talk can be converted into a live workshop for teaching attendees the use of BackTrack.

Syndicate content